Employees Are Moonlighting With AI. How HR Can Build a Policy Against It.
Picture this. It is a regular Tuesday afternoon. A marketing manager submits a 20-page competitor analysis—detailed, well-structured, and full of insights you have never seen from them before. Then you find out they did not write it. They used an AI tool, submitted the work to a client, and billed for the full hours.
As an HR professional, you feel confused. Was it wrong? Was it their time or the company's? Did the client know? You have no policy to answer any of these questions. This scenario is already playing out in workplaces everywhere—employees using AI tools to complete paid work on the side, during company hours, or on company devices. Some do not even realise it might be a problem. HR teams need policies that address this clearly.
"The line between personal productivity and policy violation is blurry. And that is the problem."
— On why AI moonlighting is so hard to governWhat AI moonlighting actually means
Moonlighting, in its traditional sense, means working a second job while employed. AI moonlighting applies the same idea to AI-assisted work. It happens when an employee uses AI tools to complete freelance work during work hours, deliver client projects faster and pocket the time difference as personal income, automate their own job tasks and spend the freed-up time working for another employer, or use company-licensed AI tools for personal and external projects.
Traditional moonlighting is easier to spot—the employee gives vague excuses, claims illness or appointments to free up time for a side hustle. AI moonlighting is different. The employee is present. Their output looks normal, sometimes better than normal. The violation is therefore far harder to detect. HR teams are managing behaviour they cannot see, using policies written for a different era.
The risks HR needs to understand
Before writing any policy, HR must understand what is actually at risk—and the concerns are operational and legal, not merely ethical. When an employee pastes client briefs or internal documents into an external AI tool, sensitive data leaves the organisation, because most consumer-grade tools offer no enterprise-level privacy guarantees. Ownership becomes murky too: if an employee uses AI to create something during work hours, who owns it—the employee, the company, or the AI provider?
Conflict of interest is a further hazard. An employee building a freelance business on AI tools may end up competing for the same clients or leaning on proprietary knowledge, directly damaging the employer. And productivity illusions distort everything: an employee can appear highly productive while quietly delivering undisclosed AI output, skewing performance reviews, team expectations, and ultimately quality.
"A strong AI policy does not just restrict. It tells employees what they can do, not just what they cannot."
— The principle behind a workable frameworkDesigning a policy that works
Most HR teams have bolted a few AI clauses onto an existing technology policy. That is not enough—AI needs its own framework. A strong one should name approved tools (which tools are permitted, for what purposes, and under what conditions, since blanket bans push usage underground), and set clear data handling rules covering what must never be entered into any AI tool: client data, internal financials, unreleased products, and personal employee data.
It should also define disclosure expectations (drafting an internal summary is not the same as passing AI work to a client as one's own), secondary employment rules requiring disclosure of any side work that could create a conflict of interest, including AI-assisted freelancing, and firm personal use boundaries stating that company-licensed tools are for company work only.
How to build it—and the disclosure question
Writing the policy is one step; making it work is another. Start with an honest, anonymous audit of which tools employees actually use and how. Involve legal and IT early, since AI policy touches data privacy law, IP, and infrastructure. Separate the policy from the punishment—most misuse stems from missing guidance, so build clarity before enforcement. Train managers to discuss AI openly, framing the goal as shared understanding rather than surveillance, and review the policy at least every six months with a named owner, because the tools change fast.
On disclosure, the honest answer is that it depends on context. For internal work—drafting a meeting summary or structuring a report—the bar can be lower. For external-facing deliverables a client or stakeholder receives, the bar should be higher, to protect quality and reputation. Employees have legitimate questions too: Can I use AI to work faster? Will it hurt my rating? If I automate part of my job, will I lose it? Policies employees do not trust are policies they will not follow—so communication must come with the policy, not after it.
Harder to detect. AI moonlighting is tough to spot because the employee is present and their output often looks normal or better. HR is managing invisible behaviour with outdated policies—a gap that needs closing.
The risks are operational and legal. Pasting briefs into external tools creates data exposure, unclear ownership creates IP disputes, and AI-assisted freelancing on company knowledge creates conflicts of interest—not just ethical concerns.
A few clauses isn't a framework. AI needs its own policy covering approved tools, data handling, disclosure expectations, secondary employment, and personal-use boundaries—telling employees what they can do, not just what they cannot.
Audit first, involve legal and IT. Run an anonymous survey to see what's really happening, then bring in legal and IT from the start. Most misuse exists because no guidance does—build clarity before enforcement.
Define disclosure, answer employees honestly. Lower the bar for internal work, raise it for client-facing deliverables. Address whether AI use affects ratings or job security—communication must accompany the policy, or it won't be trusted or followed.
